Skip to content
app-forensics
-
RdpCacheStitcher
1.1
15 mo
1 overlay
A tool that supports reconstructing useful images out of RDP cache bitmaps.
-
acstore
20240407
5 mo
1 overlay
A stand-alone implementation to read and write Attribute Container stores
-
afflib
3.7.22
::gentoo
1 overlay
Library that implements the AFF image standard
-
afl
2.57b-r2
::gentoo
1 overlay
american fuzzy lop - compile-time instrumentation fuzzer
-
aflplusplus
4.35c
::gentoo
1 overlay
Fork of AFL, the popular compile-time instrumentation fuzzer
-
aide
0.19.3
5 mo
::gentoo
2 overlays
AIDE (Advanced Intrusion Detection Environment) is a file integrity checker
-
bindiff
8
23 mo
1 overlay
Comparison tool for binary files
-
brakeman
7.1.2
6 mo
1 overlay
Static analysis tool which checks RoR applications for security vulnerabilities
-
bulk_extractor
2.1.1
14 mo
1 overlay
Scans a disk image for regular expressions and other content
-
chkrootkit
0.59
::gentoo
1 overlay
Tool to locally check for signs of a rootkit
-
cmospwd
5.1-r1
::gentoo
1 overlay
CmosPwd decrypts password stored in cmos used to access BIOS SETUP
-
dfvfs
20260411
53 d
2 overlays
Digital Forensics Virtual File System (dfVFS)
-
dfwinreg
20240316
9 mo
2 overlays
Digital Forensics Windows Registry (dfWinReg)
-
dfxml
20170921-r2
::gentoo
1 overlay
Digital Forensics XML
-
examiner
0.5-r3
::gentoo
1 overlay
Utilizes the objdump command to disassemble and comment foreign binaries
-
fatback
1.3
6 mo
1 overlay
Tool to undelete files from FAT file systems
-
foremost
1.5.7-r4
::gentoo
1 overlay
Console program to recover files based on their headers and footers
-
ftimes
3.13.0
12 mo
1 overlay
A system baselining and evidence collection tool
-
galleta
20040505_p1-r1
::gentoo
1 overlay
IE Cookie Parser
-
gitleaks
8.30.1
57 d
1 overlay
Auditing git repository for secrets and keys
-
hindsight
9999
21 mo
1 overlay
Internet history forensics for Google Chrome/Chromium
-
honggfuzz
2.6
3 mo
::gentoo
2 overlays
A general purpose fuzzer with feedback support
-
inception
0.4.2
9 mo
1 overlay
Firewire physical memory manipulation tool exploiting IEEE 1394 SBP-2 DMA
-
kerbrute
1.0.3_p20201116
57 d
1 overlay
A tool to perform Kerberos pre-auth bruteforcing
-
lazagne
2.4.3-r1
9 mo
1 overlay
Credentials recovery project
-
libbde
20240502
7 mo
2 overlays
Library and tools to access BitLocker Drive Encryption (BDE) encrypted volumes
-
libbfio
20240414
7 mo
2 overlays
Library for providing a basic file input/output abstraction layer
-
libesedb
20240420
9 mo
2 overlays
Library and tools to access the Extensible Storage Engine Database File format.
-
libevt
20221022
9 mo
1 overlay
Library and tools to access the Windows Event Log (EVT) format
-
libevtx
20240504
9 mo
2 overlays
Library and tools to access the Windows XML Event Log (EVTX) format
-
libewf
20240506
6 mo
2 overlays
Implementation of the EWF (SMART and EnCase) image format
-
libexe
20240420
9 mo
2 overlays
Library and tools to access the executable (EXE) format
-
libforensic1394
0.2-r1
39 d
1 overlay
Library for carrying out memory forensics using firewire/ieee1394
-
libfsapfs
20240429
7 mo
1 overlay
Library and tools to access the Apple File System (APFS)
-
libfsclfs
20170206
24 mo
1 overlay
Library and tools to access the Common Log File System (CLFS)
-
libfsext
20251107
7 mo
1 overlay
Library and tools to access the Extended File System
-
libfsfat
20240501
7 mo
1 overlay
Library and tools to access the File Allocation Table (FAT) file system
-
libfshfs
20240501
7 mo
1 overlay
Library and tools to access the Mac OS Hierarchical File System (HFS)
-
libfsntfs
20240501
9 mo
1 overlay
Library and tools to access the Windows New Technology File System (NTFS)
-
libfsxfs
20240501
7 mo
1 overlay
Library and tools to access the SGI X File System (XFS)
-
libfvde
20240502
7 mo
1 overlay
Library and tools to access FileVault Drive Encryption (FVDE) encrypted volumes
-
libklel
1.2.0
12 mo
1 overlay
A system baselining and evidence collection tool
-
liblnk
20240423
9 mo
2 overlays
Library and tools to access the Windows Shortcut File (LNK) format
-
libluksde
20240503
7 mo
1 overlay
Library and tools to access LUKS Disk Encryption encrypted volumes
-
libmodi
20251121
7 mo
1 overlay
Library and tools to access the Mac OS disk image formats
-
libmsiecf
20221024
9 mo
1 overlay
Library and tools to access the Microsoft Internet Explorer (MSIE) Cache Files
-
libnk2
20170127
9 mo
1 overlay
Library and tools to access the Microsoft Outlook Nickfile (NK2) format
-
libnsfdb
20170128
24 mo
1 overlay
Library and tools to access the Notes Storage Facility (NSF) file format
-
libodraw
20240505
24 mo
1 overlay
Library and tools to access to optical disc (split) RAW image files
-
libolecf
20221024
9 mo
1 overlay
Library and tools to access the OLE 2 Compound File (OLECF) format
-
libpff
20211114
9 mo
1 overlay
Library and tools to access the Personal/Offline Folder File (PFF/OFF) format
-
libphdi
20240508
7 mo
1 overlay
Library and tools to access the Parallels Hard Disk image format
-
libqcow
20240308
7 mo
1 overlay
Library and tools to access the QEMU Copy-On-Write (QCOW) image format
-
libregf
20221026
9 mo
1 overlay
Library and tools to access the Windows NT Registry File (REGF) format
-
libscca
20240427
9 mo
2 overlays
Library and tools to access the Windows Prefetch File (SCCA) format.
-
libsmraw
20240310
9 mo
1 overlay
Library and tools to access the (split) RAW image format
-
libvsapm
20240503
16 mo
1 overlay
Library and tools to access the Apple Partition Map (APM) volume system format
-
libvsgpt
20240504
7 mo
1 overlay
Library and tools to access the GUID Partition Table (GPT) volume system format
-
libvshadow
20240504
7 mo
1 overlay
Library and tools to access the Volume Shadow Snapshot (VSS) format
-
libvslvm
20240504
7 mo
1 overlay
Library and tools to access the Linux Logical Volume Manager (LVM) format
-
libvsmbr
20180325
9 mo
1 overlay
Library and tools to access the Master Boot Record (MBR) volume system format
-
libwtcdb
20170201
24 mo
1 overlay
Library and tools to access the Windows thumbnail cache (thumbcache.db)
-
log2timeline
0.66-r3
21 mo
1 overlay
Create forensic supertimelines in Perl
-
lynis
3.1.7-r1
2 yr
::gentoo
2 overlays
Security and system auditing tool
-
mac-robber
1.02-r1
::gentoo
1 overlay
mac-robber is a digital forensics and incident response tool that collects data
-
magicrescue
1.1.10-r4
::gentoo
1 overlay
Find deleted files in block devices
-
make-pdf
0.1.7-r1
9 mo
1 overlay
This tool will embed javascript inside a PDF document
-
memdump
1.01-r1
::gentoo
1 overlay
Simple memory dumper for UNIX-Like systems
-
mxtract
1.1
18 mo
1 overlay
A memory extractor & analyzer
-
mysql-magic
9999
18 mo
1 overlay
dump mysql client password from memory
-
nrich
0.1.1
2 yr
1 overlay
Enrich IPs with information about their open ports/ vulnerabilities/ software.
-
oletools
0.60.2
5 mo
1 overlay
A python tools to analyze MS OLE2 files and MS Office documents
-
openscap
1.4.3
7 mo
1 overlay
Framework which enables integration with Security Content Automation Protocol
-
openscap-daemon
0.1.10-r1
8 mo
1 overlay
Manages continuous scans of your infrastructure
-
origami-pdf
2.1.0
11 mo
1 overlay
A Ruby framework designed to parse, analyze, and forge PDF documents
-
pasco
20040505_p1-r2
::gentoo
1 overlay
IE Activity Parser
-
pcileech
4.19
18 mo
1 overlay
Direct Memory Access (DMA) Attack Software
-
pdf-parser
0.7.8
9 mo
1 overlay
This tool will parse a PDF document to identify the fundamental elements used
-
pdfid
0.2.8
9 mo
1 overlay
This tool will scan a PDF document looking for certain keyword
-
peepdf
0.4.3
9 mo
1 overlay
Python tool to explore PDF files (fork of)
-
plaso
20251119
6 mo
1 overlay
Plaso (log2timeline) is a framework to create super timelines.
-
precizer
0.17.0
14 d
1 overlay
Lightweight, high-performance file integrity verification and comparison tool
-
pytsk
20250801
7 mo
1 overlay
Python bindings for The Sleuth Kit (libtsk)
-
radamsa
0.7-r1
::gentoo
1 overlay
A general-purpose fuzzer
-
readpe
0.85.1
4 mo
2 overlays
The PE file analysis toolkit
-
reglookup
1.0.1-r1
9 mo
1 overlay
An utility for reading and querying Windows NT/2K/XP registries
-
regviewer
0.1
2 yr
1 overlay
RegViewer is GTK 2.2 based GUI Windows registry file navigator
-
rifiuti
20040505_p1-r1
::gentoo
1 overlay
Recycle Bin Analyzer
-
rkhunter
1.4.6-r2
::gentoo
1 overlay
Rootkit Hunter scans for known and unknown rootkits, backdoors, and sniffers
-
s3tk
0.3.0
9 mo
1 overlay
A security toolkit for Amazon S3
-
samhain
4.5.3
6 d
1 overlay
Advanced file integrity and intrusion detection tool.
-
scalpel
2.1_pre20210326
::gentoo
1 overlay
A high performance file carver
-
sleuthkit
4.14.0
7 mo
::gentoo
3 overlays
A collection of file system and media management forensic analysis tools
-
stegoveritas
1.11
4 d
1 overlay
Automatic image steganography analysis tool
-
tcpxtract
1.0.1
6 mo
2 overlays
Extracts files from network packet captures
-
unhide
20220611
::gentoo
1 overlay
Forensic tool to find hidden processes and TCP/UDP ports by rootkits/LKMs
-
volatility3
2.28.0
::gentoo
1 overlay
Framework for analyzing volatile memory
-
whispers
2.4.0
2 mo
1 overlay
Identify hardcoded secrets in static structured text
-
xmount
1.1.1
21 mo
1 overlay
Convert on-the-fly between multiple input and output harddisk image types
-
yara
4.5.5
::gentoo
1 overlay
A malware identification and classification tool
-
yara-x
1.18.0
::gentoo
1 overlay
A malware identification and classification tool
-
zsteg
0.2.13
11 mo
1 overlay
Detect stegano-hidden data in PNG & BMP
-
zzuf
0.15_p20220529
::gentoo
1 overlay
Transparent application input fuzzer